StackRadar

CVE-2026-40898

Medium

Advisory

Published 3 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
129
of 17,781 indexed, latest versions
Container images
120
deployed by those charts
Fix available
1 of 1
affected package

quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion

Carried by container images the latest versions of 129 of 17,781 indexed charts deploy, on 120 images.

Affected packageAffected versionsFixed inImages
github.com/quic-go/quic-gogolangv0.32.0, v0.33.0, v0.37.5, v0.38.1+27 more0.59.1120
OSV records
GHSA-vvgj-x9jq-8cj9
Also known as
GO-2026-5676

Charts affected

129 by stars
ChartLatestAffected imagesRadar Score
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/quic-go/quic-go@v0.38.1
0.59.1

Open the chart page →

2,101
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

3,706
eks-pod-identity-webhookmondu-aiVerified publisher0.3.11 of 1See more

eks-pod-identity-webhook mondu-ai 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/eks-pod-identity-webhook:latestc2ac3bad857d
github.com/quic-go/quic-go@v0.54.0
0.59.1

Open the chart page →

474
adguard-homemt1905024.0.121 of 2See more

adguard-home mt190502 4.0.12

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.737fbf01d73ecb
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,166
dify-enterpriseopenshift3.9.81 of 13See more

dify-enterprise openshift 3.9.8

1 of the 13 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

4,660
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/quic-go/quic-go@v0.58.0
0.59.1

Open the chart page →

2,525
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
github.com/quic-go/quic-go@v0.32.0
0.59.1

Open the chart page →

1,872
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
github.com/quic-go/quic-go@v0.45.0
0.59.1

Open the chart page →

1,306
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
github.com/quic-go/quic-go@v0.46.0
0.59.1

Open the chart page →

7,084
geopingrotationalVerified publisher1.3.21 of 1See more

geoping rotational 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rotationalio/geoping:1.3.034bcb6fc3cb7
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,569
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,567
chainrss30.1.281 of 8See more

chain rss3 0.1.28

1 of the 8 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

8,528
vsl-chainrss30.1.01 of 7See more

vsl-chain rss3 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

6,044
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/quic-go/quic-go@v0.39.3
0.59.1

Open the chart page →

4,610
gotifyrubxkubeVerified publisher1.3.31 of 1See more

gotify rubxkube 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
gotify/server:3.1.0be44495e4609
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

320
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
registry.k8s.io/coredns/coredns:v1.13.294caebb89dcf
github.com/quic-go/quic-go@v0.57.0
0.59.1

Open the chart page →

1,047
deeplxsnubisks0.1.01 of 1See more

deeplx snubisks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
missuo/deeplx:v1.2.232e492587678
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

479
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1

Open the chart page →

1,239
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/quic-go/quic-go@v0.46.0
0.59.1

Open the chart page →

6,779
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/quic-go/quic-go@v0.49.0
0.59.1

Open the chart page →

1,239
mediamtxstartechnicaVerified publisher0.1.11 of 1See more

mediamtx startechnica 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
bluenviron/mediamtx:1.17.19e39256d1ba3
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

576
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
github.com/quic-go/quic-go@v0.40.1
0.59.1

Open the chart page →

2,336
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:lateste753ff9f3fc4
github.com/quic-go/quic-go@v0.57.1
0.59.1

Open the chart page →

6,973
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/quic-go/quic-go@v0.32.0
0.59.1

Open the chart page →

2,015
proxyv2flyVerified publisher0.0.61 of 1See more

proxy v2fly 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
v2fly/v2fly-core:latestd06727b221fe
github.com/quic-go/quic-go@v0.55.0
0.59.1

Open the chart page →

1,426
corednsvks-helm-chartsVerified publisher1.45.01 of 1See more

coredns vks-helm-charts 1.45.0

1 of the 1 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
coredns/coredns:1.13.19b9128672209
github.com/quic-go/quic-go@v0.55.0
0.59.1

Open the chart page →

887
wardnwardnVerified publisher0.1.01 of 3See more

wardn wardn 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

86
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-40898.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/quic-go/quic-go@v0.59.0
0.59.1

Open the chart page →

1,456

Container images carrying it

120 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
github.com/quic-go/quic-go@v0.57.1
0.59.1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
github.com/quic-go/quic-go@v0.57.1
0.59.1
1
library/caddy:2.660fb54d36b4b
github.com/quic-go/quic-go@v0.32.0
0.59.1
1
library/caddy:2.11.2-alpine834468128c76
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
library/caddy:2.9-alpineb4e3952384eb
github.com/quic-go/quic-go@v0.48.2
0.59.1
1
library/traefik:v2.11.00a5157f742d2
github.com/quic-go/quic-go@v0.40.1
0.59.1
1
library/traefik:3.3.5104204dadedf
github.com/quic-go/quic-go@v0.48.2
0.59.1
1
library/traefik:v2.10.11489caffaedb
github.com/quic-go/quic-go@v0.33.0
0.59.1
1
library/traefik:2.10.61957e3314f43
github.com/quic-go/quic-go@v0.39.1
0.59.1
1
library/traefik:v3.6.1334d5089d0b41
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
linuxserver/wireguard:latestbf03578ef731
github.com/quic-go/quic-go@v0.57.0
0.59.1
1
linuxserver/wireguard:1.0.20260223-r0-ls122dca67384e3e9
github.com/quic-go/quic-go@v0.57.0
0.59.1
1
louislam/uptime-kuma:1.23.1396510915e6be
github.com/quic-go/quic-go@v0.40.1-0.20240101045026-22b7f7744eb6
0.59.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
github.com/quic-go/quic-go@v0.40.1-0.20240101045026-22b7f7744eb6
0.59.1
1
lumenvox/admin-portal:7.112310cf52f79
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
lumenvox/management-api:7.16420a6e7d6c2
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
megaease/easegress:latestfad1c7452958
github.com/quic-go/quic-go@v0.40.1
0.59.1
1
missuo/deeplx:v1.2.232e492587678
github.com/quic-go/quic-go@v0.57.1
0.59.1
1
netbirdio/relay:0.45.1872e3add0e1e
github.com/quic-go/quic-go@v0.48.2
0.59.1
1
netbirdio/reverse-proxy:0.72.43104d5ca3a76
github.com/quic-go/quic-go@v0.55.0
0.59.1
1
novosga/novosga:latest34b9acbe6e51
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
github.com/quic-go/quic-go@v0.50.1
0.59.1
1
photoprism/photoprism:251130db16ee6b1ba3
github.com/quic-go/quic-go@v0.55.0
0.59.1
1
pinclr/v2ray-proxy:latestf37f250b7091
github.com/quic-go/quic-go@v0.33.0
0.59.1
1
rotationalio/geoping:1.3.034bcb6fc3cb7
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
rotationalio/rotational-api:1.3.0f1a2d05d8fff
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/quic-go/quic-go@v0.39.3
0.59.1
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
github.com/quic-go/quic-go@v0.48.2
0.59.1
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
superseriousbusiness/gotosocial:0.22.10078ca451dda
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
github.com/quic-go/quic-go@v0.40.1
0.59.1
1
syncthing/syncthing:2.1.07c60eb0ec887
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
udhos/gateboard:1.12.53acc0e7599bf
github.com/quic-go/quic-go@v0.55.0
0.59.1
1
v2fly/v2fly-core:latestd06727b221fe
github.com/quic-go/quic-go@v0.55.0
0.59.1
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/avistotelecom/kubebrowser:0.10.0a354b8dc7e6a
github.com/quic-go/quic-go@v0.54.0
0.59.1
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
github.com/quic-go/quic-go@v0.46.0
0.59.1
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
github.com/quic-go/quic-go@v0.54.0
0.59.1
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
github.com/quic-go/quic-go@v0.45.2
0.59.1
1
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
github.com/quic-go/quic-go@v0.49.1
0.59.1
1
ghcr.io/chrxmvtik/gitlab-mr-conform:0.5.2b2eb79fc99cb
github.com/quic-go/quic-go@v0.59.0
0.59.1
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
github.com/quic-go/quic-go@v0.55.0
0.59.1
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
github.com/quic-go/quic-go@v0.54.0
0.59.1
1
ghcr.io/happymooguild/wardn-backend:0.1.023ee1b8cfc3c
github.com/quic-go/quic-go@v0.59.0
0.59.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.